I have been trying to find facts related to information security. I am doing a presentation next week to the management team and I really, really want to catch their attention. I am looking for things like (I am making up the numbers, as an example):

- 80% of all attacks comes from inside an organization- 75% of all web sites are vulnerable to XSS attacks- Etc

So, do you know where I can find a reliable source for impressive facts?

I would also consider the Verizon 2009 Data Breach Investigations Report. Though I might question the purview, it has a lot of information on the breaches they encountered and corresponding mitigation. The 2010 is due out this summer and they supposedly teamed with the Secret Squirrels.